False Negative: ConstantExpAppearsNonConstant.ql misses expressions that stay constant after trivial local rewrites.
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 48/100
Hướng nghiên cứu
Bắt đầu với Likely Bugs/Arithmetic/ConstantExpAppearsNonConstant.ql và kiểm tra cách nó truyền các kết quả hằng số qua các biến cục bộ và các biểu thức được viết lại. Xem xét PosCase1.java, PosCase3_Var1.java và PosCase3_Var2.java như các ví dụ bị ảnh hưởng. Công việc được hoàn tất khi truy vấn nhận diện các biểu thức hằng số được mô tả mà không làm mất hành vi phát hiện hiện có.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Version
codeql 2.24.3
Checker
- Checker id:
Likely Bugs/Arithmetic/ConstantExpAppearsNonConstant.ql - Checker description: This checker detects expressions that always evaluate to the same constant value but are not recognized as compile-time constants by the compiler, often due to containing non-constant sub-expressions that don't affect the final result.
Description of the false negative
These cases still reduce to a constant result at runtime. One multiplies by zero. The others use true || condition, which is still always true regardless of the non-constant boolean input.
The only change is that the constant-looking behavior is expressed through locals or a slightly different spelling.
Affected test cases
PosCase1.java
nonConstant * 0 still evaluates to zero regardless of the non-constant operand.
PosCase3_Var1.java and PosCase3_Var2.java
Both variants are still logical constants. Boolean.TRUE || condition and alwaysTrue || condition should both be recognized as always true.
Cause analysis
This looks like a propagation gap. Likely Bugs/Arithmetic/ConstantExpAppearsNonConstant.ql appears to lose the constant result once the expression is one step less direct, even though the same algebraic reasoning still applies.
That makes the query miss a kind of bug it should be well suited to catch.
Reproduction code
PosCase1.java
// Multiplication by zero with integer literal zero operand should be flagged as always evaluating to zero.
package scensct.core.pos;
public class PosCase1 {
public PosCase1() {
int nonConstant = getNonConstant(); // Non-constant subexpression
int result = nonConstant * 0; // Multiplication by zero, always zero
// Use result in a conditional to emphasize constant evaluation
if (result == 0) {
// This branch is always taken
System.out.println("Always zero");
}
}
private int getNonConstant() {
return (int) (Math.random() * 100); // Non-constant value
}
}
References
None known.
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 16 giờ
- Pull request đã merge (30 ngày)
- 143
Hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của github/codeql
-
agentic-workflows
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
-
false-positive javascript
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 84/100
-
C#: cs/simplifiable-boolean-expression false positive on Nullable<bool> compared with a literal Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
-
false-positive
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
Tất cả issue của github/codeql
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
punkpeye/mcp-remote#369 ·
-
Mend: dependency security vulnerability untriaged
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 86/100
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
-
CVE-2024-24786 CPE mismatch Đang mởbug
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 90/100
cisagov/vulnrichment#337 ·
-
bug DUP Reservations
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
bcgov/reserve-rec-public#896 ·